Threat ResQ

Compliance

PCI DSS: The Complete Guide to Payment Card Data Security Compliance

The Payment Card Industry Data Security Standard (PCI DSS) is a global security standard for any organization that stores, processes, or transmits cardholder data. It's maintained by the PCI Security Standards Council, f

8 min readLast reviewed September 3, 2026Threat ResQ Technologies

PCI DSS: The Complete Guide to Payment Card Data Security Compliance

Executive Summary

The Payment Card Industry Data Security Standard (PCI DSS) is a global security standard for any organization that stores, processes, or transmits cardholder data. It's maintained by the PCI Security Standards Council, founded by the major card brands, and applies to merchants and service providers of every size — from a small e-commerce shop to a large payment processor — with the specific validation requirements scaling to transaction volume. This guide covers the 12 core requirements, how merchant and service provider levels work, the Self-Assessment Questionnaire (SAQ) and formal assessment paths, and how getTRAC automates the evidence collection an ongoing PCI DSS program depends on.

Key Takeaways

  • PCI DSS applies to any organization that stores, processes, or transmits cardholder data — not just payment processors.
  • The standard's requirements are organized around securing the Cardholder Data Environment (CDE) — the systems and network segments that touch card data.
  • Validation requirements scale by merchant or service provider level, based on annual transaction volume, from a Self-Assessment Questionnaire up to a formal Report on Compliance by a Qualified Security Assessor (QSA).
  • Reducing the scope of the CDE — through network segmentation or by using a compliant third-party payment processor — is usually the single biggest lever for reducing compliance burden.
  • PCI DSS is not a law; it's a contractual requirement enforced by the card brands and acquiring banks, with non-compliance risking fines, increased transaction fees, or loss of card-processing privileges.

What PCI DSS covers {#what-it-covers}

PCI DSS applies to any entity that stores, processes, or transmits cardholder data, or that could impact the security of that data — this includes merchants accepting card payments, payment processors, and any service provider connected to a merchant's cardholder data environment. Unlike a government regulation, PCI DSS is a contractual obligation set by the card brands (Visa, Mastercard, American Express, Discover, JCB) through the PCI Security Standards Council, and enforced through merchant agreements with acquiring banks.

The 12 requirements {#twelve-requirements}

PCI DSS organizes its controls into 12 requirements, grouped into six control objectives:

  • Build and maintain a secure network and systems — firewall configuration, and not using vendor-supplied default passwords or security parameters.
  • Protect account data — protecting stored cardholder data, and encrypting transmission of cardholder data across open, public networks.
  • Maintain a vulnerability management program — protecting systems against malware, and developing and maintaining secure systems and software.
  • Implement strong access control measures — restricting access to cardholder data by business need-to-know, identifying and authenticating access to system components, and restricting physical access to cardholder data.
  • Regularly monitor and test networks — logging and monitoring all access to system components and cardholder data, and regularly testing security of systems and networks (including vulnerability scanning and penetration testing).
  • Maintain an information security policy — a formal policy that addresses information security for all personnel.

Merchant and service provider levels {#levels}

Validation requirements scale to how much card volume an organization processes:

  • Merchant Level 1 — over 6 million transactions annually, or any merchant a card brand designates as Level 1. Requires an annual Report on Compliance (ROC) by a QSA.
  • Merchant Level 2–3 — lower transaction thresholds, typically permitted to self-assess via a Self-Assessment Questionnaire (SAQ), though brand-specific requirements vary.
  • Merchant Level 4 — smaller merchants, generally eligible for SAQ-based self-assessment.
  • Service providers are similarly tiered, with Level 1 service providers (generally handling large volumes) also requiring an annual QSA-led assessment.

Exact thresholds and requirements vary by card brand and by acquiring bank, so organizations should confirm their specific level directly with their acquirer rather than assuming a threshold applies universally.

SAQ types and the assessment process {#assessment-process}

Organizations eligible for self-assessment select from several Self-Assessment Questionnaire (SAQ) types based on how they handle card data — for example, SAQ A applies to merchants who fully outsource card data handling to a compliant third party with no card data touching their own systems, while SAQ D applies to merchants and service providers handling card data directly and covers the full requirement set. Level 1 merchants and service providers instead undergo a formal Report on Compliance assessment led by a Qualified Security Assessor, which typically includes on-site (or remote-equivalent) testing of controls across the Cardholder Data Environment.

Scoping and the Cardholder Data Environment {#scoping}

The Cardholder Data Environment (CDE) is the set of people, processes, and technology that store, process, or transmit cardholder data, plus any connected systems that could impact its security. Accurately scoping the CDE — and using network segmentation to isolate it from the rest of the environment — is typically the single most effective way to reduce PCI DSS compliance burden, since systems genuinely outside the CDE fall outside the assessment scope. Many organizations reduce their PCI DSS footprint substantially by routing card transactions through a compliant third-party payment processor rather than handling raw card data themselves.

How getTRAC helps with PCI DSS {#how-gettrac-helps}

getTRAC maps ongoing platform activity to PCI DSS requirements alongside seven other frameworks (ISO 27001, SOC 2, GDPR, DPDP, HIPAA, RBI, NIST), generating continuous evidence for access reviews, vulnerability scans, and log monitoring rather than assembling it before an assessment. For organizations preparing for a first assessment or scoping a Cardholder Data Environment, Compliance Consulting and VAPT pair a human team with the platform to run the readiness work and the required vulnerability/penetration testing.

FAQ {#faq}

Does PCI DSS apply to small merchants? Yes — PCI DSS applies to any organization that stores, processes, or transmits cardholder data, regardless of size, though smaller merchants (Level 4) are generally eligible for a lighter-weight Self-Assessment Questionnaire rather than a formal QSA-led assessment.

Is PCI DSS a law? No — it's a contractual requirement set by the payment card brands through the PCI Security Standards Council, enforced through merchant agreements with acquiring banks rather than by government regulators.

What's the fastest way to reduce PCI DSS scope? Accurately scoping and segmenting the Cardholder Data Environment, and where possible, routing card transactions through a compliant third-party payment processor so raw card data never touches your own systems — both meaningfully shrink what falls inside the assessment.

Does PCI DSS require a penetration test? Yes, for organizations in scope for the full requirement set — regular vulnerability scanning and periodic penetration testing of the Cardholder Data Environment are explicit PCI DSS requirements, with frequency depending on merchant/service provider level.

Frequently asked questions

Does PCI DSS apply to small merchants?

Yes — PCI DSS applies to any organization that stores, processes, or transmits cardholder data, regardless of size, though smaller merchants (Level 4) are generally eligible for a lighter-weight Self-Assessment Questionnaire rather than a formal QSA-led assessment.

Is PCI DSS a law?

No — it's a contractual requirement set by the payment card brands through the PCI Security Standards Council, enforced through merchant agreements with acquiring banks rather than by government regulators.

What's the fastest way to reduce PCI DSS scope?

Accurately scoping and segmenting the Cardholder Data Environment, and where possible, routing card transactions through a compliant third-party payment processor so raw card data never touches your own systems — both meaningfully shrink what falls inside the assessment.

Ask TIARA about this article

Get a grounded answer on PCI DSS compliance, or ask your own question.

Talk to an Expert

We use cookies for essential function and, with consent, analytics. Cookie Policy